CVE-2025-12985: License Service: Privilege escalation vulnerability
Published Jan 20, 2026
·Updated
IBM Licensing Operator incorrectly assigns privileges to security critical files which could allow a local root escalation inside a container running the IBM Licensing Operator image.
Affected Software
0 affected components
Remediation
Information
The fix is provided in License Service version 4.2.18.
Event History
Jan 20, 2026
CVE Published
via MITRE·02:50 PM
Data Sourced
via MITRE·02:50 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Jan 30, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-12985?
The severity of CVE-2025-12985 is rated high with a score of 8.4.
2
How do I fix CVE-2025-12985?
To fix CVE-2025-12985, upgrade to License Service version 4.2.18.
3
What type of vulnerability is CVE-2025-12985?
CVE-2025-12985 is a privilege escalation vulnerability affecting the IBM Licensing Operator.
4
What are the potential impacts of CVE-2025-12985?
CVE-2025-12985 could allow a local root escalation inside a container running the IBM Licensing Operator image.
5
Who is affected by CVE-2025-12985?
Any users or systems running the IBM Licensing Operator image are potentially affected by CVE-2025-12985.